Secure Route Establishment in Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Ad hoc wireless networks face inefficiencies in authentication processes due to the need for complex mutual authentication between all neighboring nodes, consuming significant time and processor resources, especially in scenarios without traditional infrastructure like base stations.

Innovation Solution

A method that allows nodes in a wireless network to selectively form security associations with only particular neighboring nodes, using route request and reply messages to establish ephemeral and secure routes, and employing multi-class routing tables to differentiate between secure and non-secure links, thereby reducing unnecessary authentication processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complex mutual authentication is performed between all neighboring nodes in ad hoc wireless networks, then security is improved, but time consumption and processor resource usage increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the authentication requirement from being universally applied to all neighboring nodes and selectively applies it only to nodes that form security associations. This is achieved by having nodes maintain authentication states and selectively authenticating only with specific neighbors rather than all neighbors, thereby reducing authentication time while maintaining security where needed.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of performing complete mutual authentication with all neighboring nodes, the patent implements partial authentication only with nodes that require security associations. Nodes can communicate with non-authenticated neighbors using unsecured links for non-sensitive data, performing authentication only partially with specific nodes rather than all nodes, reducing overall authentication time and processor usage.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If complex mutual authentication is performed between all neighboring nodes in ad hoc wireless networks, then security is improved, but processor resource consumption increases significantly

Engineering Contradiction:
ImprovesecurityVSAvoidprocessor resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the authentication requirement from being universally applied to all neighboring nodes and selectively applies it only to nodes that form security associations. This is achieved by having nodes maintain authentication states and selectively authenticating only with specific neighbors rather than all neighbors, thereby reducing processor resource consumption while maintaining security where needed.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of performing complete mutual authentication with all neighboring nodes, the patent implements partial authentication only with nodes that require security associations. Nodes can communicate with non-authenticated neighbors using unsecured links for non-sensitive data, performing authentication only partially with specific nodes rather than all nodes, reducing overall processor resource consumption and energy usage.

Inventive Principle:
Principle #16Partial or excessive action

3Device complexity

If centralized authentication procedure is used with a single IAP for all supplicants, then authentication management is simplified, but the system becomes impractical for nodes outside wireless range of IAP

Engineering Contradiction:
Improveauthentication management complexityVSAvoidnetwork coverage flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the centralized authentication architecture into distributed authentication capabilities. Each node in the ad hoc network can independently perform authentication with its neighbors, rather than all nodes depending on a single centralized IAP. This segmentation allows nodes outside IAP range to participate in the network while maintaining authentication security through peer-to-peer authentication mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces authentication state information as an intermediary mechanism that enables nodes to determine whether authentication is needed before communication. Nodes exchange authentication state information to identify which neighbors require security associations, allowing the system to adapt between centralized and distributed authentication modes depending on network conditions and node capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8161283B2Method and device for establishing a secure route in a wireless network
Publication Date: 2012.04.17 ARRIS ENTERPRISES LLC
  • US8161283B2 patent drawing
  • US8161283B2 patent drawing
  • US8161283B2 patent drawing

AI summary

A method for establishing a secure route in a wireless network as provided improves network efficiency. According to one aspect, the method includes receiving at a first node in the wireless network a route request message from a second node, where the second node and the first node have not been mutually authenticated. The route request message is then forwarded from the first node to a third node. A route reply message is then received at the first node from the third node. The first node is then mutually authenticated with the second node in response to receiving the route reply message at the first node.